{"id":19117,"date":"2020-12-14T10:03:35","date_gmt":"2020-12-14T15:03:35","guid":{"rendered":"https:\/\/staging.elteni.com\/?p=19117"},"modified":"2020-12-14T10:03:35","modified_gmt":"2020-12-14T15:03:35","slug":"solarwinds-orion-delivers-backdoor-trojan-to-worldwide-networks","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=19117","title":{"rendered":"Solarwinds ORION delivers backdoor Trojan to worldwide networks"},"content":{"rendered":"<h2>Fireye detected that Solarwinds Orion is being used by attackers to steal sensitive company data.<\/h2>\n<p><a href=\"https:\/\/www.fireeye.com\/\" data-cke-saved-href=\"https:\/\/www.fireeye.com\/\">Fireye\u2019s<\/a> threat research division found that a highly sophisticated and evasive attacker compromised the <a href=\"https:\/\/www.solarwinds.com\/solutions\/orion\" data-cke-saved-href=\"https:\/\/www.solarwinds.com\/solutions\/orion\">Solarwind\u2019s Orion<\/a> IT monitoring and management platform to deliver a backdoor trojan. It is suspected that the campaign has started as early as April 2020 and is currently ongoing. It appears the attackers were moving laterally across networks and stealing data.<\/p>\n<p>Fireye stated that after it sits dormant for up to two weeks, it retrieves and executes command from command-and-control servers on the internet. The commands it downloads allow for the ability to transfer files, execute files, profile the system, reboot the machine, and disable system services. The malware disguises its network traffic and stores the data collection within legitimate Solarwinds\u2019 plugin configuration files.<\/p>\n<p>\u201cFireEye has detected this activity at multiple entities worldwide. The victims have included government, consulting, technology, telecom and extractive entities in North America, Europe, Asia and the Middle East. We anticipate there are additional victims in other countries and verticals. FireEye has notified all entities we are aware of being affected.\u201d<\/p>\n<p>It is important to note that Fireye only detected this for businesses that use their products. It is very likely there are others that are affected.<\/p>\n<h2 class=\"null\">What is the takeaway here?<\/h2>\n<p>Many internal IT teams and IT managed service providers use the popular Solarwinds products to manage and monitor networks.<\/p>\n<p>Elteni encourages you to check with Internal IT teams or your IT managed service provider to determine if any Solarwinds products are in use, including ORION, and if they are, have the IT Teams immediately assess the environment and patch Solarwinds.<\/p>\n<p>Remote monitoring and management tools are often disregarded as a potential threat to a business because the name implies the opposite. Remote monitoring and management tools that can establish any type of connection outbound or allow a connection inbound should be treated as a hole in your network, and should be monitored and reviewed on a periodic basis.<\/p>\n<p>Elteni&#8217;s risk assessments, penetration tests, and vulnerability assessments can help you detect these holes in your environment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fireye detected that Solarwinds Orion is being used by attackers to steal sensitive company data. Fireye\u2019s threat research division found that a highly sophisticated and evasive attacker compromised [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":19118,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[114,67,68,3,91,101,102,28,23,16,17,25,15,123,35,124,19],"tags":[],"class_list":["post-19117","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-alternative-asset-management","category-awareness","category-cloud","category-cyber","category-exploit","category-hackers","category-hedge-fund","category-identity-theft","category-insider-threats","category-malware","category-password","category-pii","category-privacy","category-remote-management","category-reverse-shell","category-rmm","category-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Solarwinds ORION delivers backdoor Trojan to worldwide networks - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=19117\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Solarwinds ORION delivers backdoor Trojan to worldwide networks - Insights\" \/>\n<meta property=\"og:description\" content=\"Fireye detected that Solarwinds Orion is being used by attackers to steal sensitive company data. Fireye\u2019s threat research division found that a highly sophisticated and evasive attacker compromised [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=19117\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2020-12-14T15:03:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2020\/12\/remote-network-monitoring-scaled-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1703\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Elteni\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Elteni\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117\"},\"author\":{\"name\":\"Elteni\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\"},\"headline\":\"Solarwinds ORION delivers backdoor Trojan to worldwide networks\",\"datePublished\":\"2020-12-14T15:03:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117\"},\"wordCount\":360,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/remote-network-monitoring-scaled-1.jpg\",\"articleSection\":[\"Alternative Asset Management\",\"Awareness\",\"Cloud\",\"Cyber\",\"Exploit\",\"Hackers\",\"Hedge Fund\",\"Identity Theft\",\"Insider threats\",\"Malware\",\"Password\",\"PII\",\"Privacy\",\"Remote Management\",\"Reverse Shell\",\"RMM\",\"Vulnerability\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117\",\"name\":\"Solarwinds ORION delivers backdoor Trojan to worldwide networks - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/remote-network-monitoring-scaled-1.jpg\",\"datePublished\":\"2020-12-14T15:03:35+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/remote-network-monitoring-scaled-1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/remote-network-monitoring-scaled-1.jpg\",\"width\":2560,\"height\":1703,\"caption\":\"Remote Network Monitoring\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=19117#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Solarwinds ORION delivers backdoor Trojan to worldwide networks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\",\"name\":\"Elteni\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"Elteni\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=2\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Solarwinds ORION delivers backdoor Trojan to worldwide networks - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=19117","og_locale":"en_US","og_type":"article","og_title":"Solarwinds ORION delivers backdoor Trojan to worldwide networks - Insights","og_description":"Fireye detected that Solarwinds Orion is being used by attackers to steal sensitive company data. Fireye\u2019s threat research division found that a highly sophisticated and evasive attacker compromised [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=19117","og_site_name":"Insights","article_published_time":"2020-12-14T15:03:35+00:00","og_image":[{"width":2560,"height":1703,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2020\/12\/remote-network-monitoring-scaled-1.jpg","type":"image\/jpeg"}],"author":"Elteni","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Elteni","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=19117#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19117"},"author":{"name":"Elteni","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075"},"headline":"Solarwinds ORION delivers backdoor Trojan to worldwide networks","datePublished":"2020-12-14T15:03:35+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19117"},"wordCount":360,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19117#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2020\/12\/remote-network-monitoring-scaled-1.jpg","articleSection":["Alternative Asset Management","Awareness","Cloud","Cyber","Exploit","Hackers","Hedge Fund","Identity Theft","Insider threats","Malware","Password","PII","Privacy","Remote Management","Reverse Shell","RMM","Vulnerability"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=19117","url":"https:\/\/www.elteni.com\/insights\/?p=19117","name":"Solarwinds ORION delivers backdoor Trojan to worldwide networks - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19117#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19117#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2020\/12\/remote-network-monitoring-scaled-1.jpg","datePublished":"2020-12-14T15:03:35+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=19117#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=19117"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=19117#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2020\/12\/remote-network-monitoring-scaled-1.jpg","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2020\/12\/remote-network-monitoring-scaled-1.jpg","width":2560,"height":1703,"caption":"Remote Network Monitoring"},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=19117#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"Solarwinds ORION delivers backdoor Trojan to worldwide networks"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075","name":"Elteni","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"Elteni"},"url":"https:\/\/www.elteni.com\/insights\/?author=2"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19117"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/19117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/19118"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}